NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
pub.dev · #2509 most downloaded on pub.dev
The at_client library is the non-platform specific Client SDK which provides the essential methods for building an app using the atProtocol.
Last release today
07 Oct 2026
Release timing varies
gaps range from 8 days to 4 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
3 versions withdrawn
withdrawn after publishing
6 years old
129 releases · first in 2020
feat: AtSignServerCheck, AtSignServerState, checkAtSignServer and AtSignLogger come through package:at_client/at_client.dart, so an app no longer need
AtSignServerCheck, AtSignServerState, checkAtSignServer and
AtSignLogger come through package:at_client/at_client.dart, so an app no
longer needs at_lookup or at_utils for them.fix: after an upgrade from 3.14.0, sync no longer stops for good, a restart no longer skips the notifications sent while the client was not running, a
local: record put back through the AtKey that read it can still be
read. A device a 3.15.0 prerelease left in that state recovers, except for an
app's own local: value shaped like ciphertext (base64 of a multiple of 16
bytes), which the app has to write again.Hive.init itself.Atsign.open refused by the atServer on
a device that has synced returns a client in the refused state rather than
throwing.AtChops and no key source, as
at_onboarding_cli 1.x builds one, uses the keys that AtChops holds again.readBy and wasMarkedReadByMe count a read receipt this client sent
before a restart, so markReadByMe no longer sends it a second time.CryptoConfig.supersededCkGrace) before it is cleaned up, so a recipient
can still open a notification sent under it just before the rotation.NotificationParams.forUpdate(..., ephemeral: true), send(..., ephemeral: true)): an atServer that supports
it delivers it without storing it, for at most 2 minutes. It cannot carry a
ttr or be cached at the recipient.ttln, so it no longer drifts at each hop.at_commons ^5.19.0.at_auth ^4.0.0-rc4: PendingEnrollment.awaitApproval on
an expired or unknown enrollment fails at once, with the atServer's reason.ensureReachable's result says whether this client can open what
peers seal to the namespace (AtReachabilityResult.holdsPrivate).* grant too.* can be approved; it was
refused for having no namespace to be sent its keys in.atClient.schemeOf(key) tells how a value another atSign shared was
protected: legacy or post-quantum, and under which KEM.
AtNotification.receivedUnder, passed as the cryptoProviderId of
NotificationService.send or AtClientBindings.notify (new there), lets an
app answer in the scheme it was asked in. A class that overrides
AtClientBindings.notify must add the parameter.AtRpc request can name its cryptoProviderId, and an AtRpc
server answers each request in the scheme it arrived in.AtRpc reply to a requester that cannot open a post-quantum answer
goes out under the server's default scheme, and a reply that could not be
sent is retried rather than dropped.AtRpc requests, from one client or several, no longer
share a request id, which could drop one or hand a caller another's response.AtKey reused for several puts or notifications carries nothing
over from one to the next.shouldEncrypt: false
is stored as given and treated as plain: the put drops isEncrypted,
ivNonce and the other encryption fields an app sets on the key's metadata.appMetadata no longer chooses the
provider for a notification the SDK encrypts; pass cryptoProviderId.noCommit put that falls back to legacy encryption still asks the
atServer not to record a commit.One column per quarter.
build: requires at_auth ^4.0.0-rc3, which releases a keyfile lock left behind by a process that stopped mid-write within 5 seconds.
at_auth ^4.0.0-rc3, which releases a keyfile lock left
behind by a process that stopped mid-write within 5 seconds.at_lookup ^3.7.0-rc3, whose notification connection logs
Heartbeat OK: lastReceipt <time> on each answered heartbeat again.isInSync() answers true once a client with a sync regex, or on an
enrollment limited to some namespaces, has pulled everything its filter
admits, rather than staying false until the next write the filter admits.feat (experimental): invitations, including to someone with no atSign yet: AtClientInvitations in at_client_mixins.dart, also as the Invitations mixin
AtClientInvitations in at_client_mixins.dart, also as the Invitations
mixin. An invitation is a link plus a separate code and can carry encrypted
content; the invitee previews and accepts it, and the inviter decides it
once.remoteLocalPref sends to the atServer now
sends its content key there too, so the atSign's other clients can read it.AtCollection that holds an item this atSign shared
post-quantum no longer fails.WithdrawnSigningKeyException, which says which.EnvelopeSigning.publicKeyCacheSettings no longer
takes resetOnLookup; a fetched key is kept for a fixed time.showHiddenKeys lists them.ensureReachable on a client with no AtKeysIo no longer publishes a
key only that process could open. It answers AtReachability.noKeySource,
which an exhaustive switch must now handle.…for a name with no dot; namespace is deprecated in favour of idAndNamespace.
AtClientPreference.posture (PqPosture.legacy, the default, pqReady or
pqActive): ML-DSA-65 signing, ML-KEM and X-Wing key establishment,
per-namespace keys, a signing root, secret conveyance at enrollment approval,
and key rotation. The default posture runs none of it. The 3.14.0
secret-sharing substrate changed shape.Atsign('@alice') lifecycle verbs: activate, enroll /
resumeEnrollment, open (serves local storage while offline) and
authenticatesAs. client.enrollments lists, approves, denies and revokes,
and issues OTPs and SPPs. buildAtClient(...) builds a client, and
AtClientManager.getInstance().use(client) makes it current.AtClientStorage, defaulting to
HiveAtClientStorage, with SqliteAtClientStorage and
InMemoryAtClientStorage in package:at_client/sqlite.dart.client.connection reports online, offline or refused;
attempt() and awaitOnline() retry. monitorSilenceTimeout (default 60s)
rebuilds a notification connection that has gone quiet.AtClient.stop() ends everything the client started and releases its
storage, so the process can exit. A stopped client cannot be restarted.NotificationService.send() encrypts under the namespace the caller
named and throws ArgumentError for a name with no dot; namespace is
deprecated in favour of idAndNamespace.appMetadata and immutable, expired records are reclaimed, and
AtCollection no longer duplicates, misses or deletes live items.clientConfig again,
AtClientImpl.create refuses a storage its cached client doesn't hold, and
closing a storage no longer races a concurrent attach.AtClientManager.setCurrentAtSign and
fromAuthSession; AtClient.atChops; AtClientPreference.decryptPackets,
tlsKeysSavePath, pathToCerts, hiveStoragePath and commitLogPath.at_auth ^4.0.0-rc2, at_lookup ^3.7.0-rc2, at_commons
^5.18.0, at_chops ^3.6.0 and at_persistence_secondary_server ^5.3.0.feat (experimental): per-APKAM same-atSign secret-sharing substrate — AtClientSecretSharing / PairwiseSecretSharing (mixins KeyPackageRegistration, En
AtClientSecretSharing / PairwiseSecretSharing (mixins KeyPackageRegistration,
EnvelopeSigning), SecretStore, KeyPackage, SecretEnvelope, and the
EnrollmentDirectory seam. Secrets travel in X-Wing-sealed (pqSeal),
APKAM-signed __ssenv envelopes addressed by kpid; key packages are
enrollment-internal (conveyed via enroll:request, discovered via the gated
enroll:listns verb) and never published. The whole surface is
@experimental — the wire shape is subject to change pending the atServer
verb work — and requires at_chops ^3.3.0 (pqSeal/pqOpen).deprecated: AtClient.startCompactionJob and AtClient.stopCompactionJob are retained for source compatibility but are now no-ops (a commit-log-free cli…
AtClientPreference.networkTimeout — when set on the preference used
to create an AtClient, it becomes the process-wide network-timeout default
(AtNetworkTimeouts.defaultTimeout, capped at 60s), bounding every atServer
connect / atDirectory lookup / operation so a dead network can't hang the SDK.
Supersedes the misnamed outboundConnectionTimeout (a socket idle time).
Requires at_commons ^5.13.0 (#1923).at_lookup: ^3.6.0, at_auth: ^3.2.0 — the bounded socket
connects and the deadline-driven validateAtServer live in those versions;
with older ones resolved, networkTimeout would set a policy nothing reads.at_persistence_secondary_server
5.0.0 — the client is now commit-log-free. The client no longer maintains a
local commit log or runs commit-log compaction; sync tracks its progress
with a persisted pull cursor, and key-expiry processing is driven by the
keystore's nextExpiresAt / peekNewlyAvailable surface. Requires
at_persistence_secondary_server ^5.0.0.AtClient.startCompactionJob and AtClient.stopCompactionJob
are retained for source compatibility but are now no-ops (a commit-log-free
client has no commit log to compact); they will be removed in a future
major release.FileTransferService and FileTransferObject are now marked
@Deprecated. The SDK file-sharing API (uploadFile / downloadFile /
shareFiles / reuploadFiles) has moved to the app layer and will be
removed, along with the archive dependency, in the next major version
(#1113).cron dependency — it was only used by the
commit-log compaction that the at_persistence_secondary_server 5.0.0
migration removed, and nothing in the client imports it (#1378). uuid is
already on ^4.0.0.chore: deprecated atClientManager param in the factories of AtClient, NotificationService, and SyncService
Several significant enhancements to the API to make it much easier to use.
send, to NotificationService which is much
easier to use than the old (still fine to use) notify method.factory AtRpc.server to make it much simpler to create AtRpc
servers.AtClientPreference.crypto, CryptoConfig, and
CryptoProvider.CryptoStorage to provider context for provider-owned local /
remote state, plus CryptoPolicy.onProviderNotFound for lazy
provider registration with a single retry.CSubItemUpdated events
that surfaced under EventSource.notifs (and EventSource.both)
when the keystore mirror landed under a key shape the readback
couldn't resolve, or raced ahead of sync writing the bare key.Major documentation uplift
And some tech debt cleanup
atClientManager param in the factories of AtClient, NotificationService, and SyncServicesync:from: request returns no entries because
the entire (lastReceivedServerCommitId, serverCommitId] range was filtered
out server-side (apkam namespace scope, syncRegex, or skipDeletesUntil),
advance the persisted server-commit cursor to the sync-start serverCommitId
snapshot instead of breaking out without advancing. Subsequent sync rounds
no-op until the server actually advances past it, rather than re-probing
the same filtered range every round.Nothing published for this version
Nothing published for this version
- chore(deps): at_auth ^3.0.0 - chore(deps): at_chops ^3.0.0
build(deps): Updated archive dependency to ^4.0.7
.toString() methods are JSON serialized
stringsfix: AtRpc - prevent NACK/ACK race when handling request mutex acquisition
chore: removed @experimental annotation from AtRpc and AtCollection
@experimental annotation from AtRpc and AtCollection// ignore: experimental_member_use for usages of the
still-experimental AtTelemetryfeat: introduce single-responder mode in AtRpc enabling redundancy support in request-response services relying on AtRpc. This feature is coupled with
enableRequestMutex flag that controls it.feat: add optional useRemoteAtServer flag to AtClient getKeys and getAtKeys so that apps can ask to fetch directly from atServer rather than the local
useRemoteAtServer flag to AtClient getKeys and
getAtKeys so that apps can ask to fetch directly from atServer rather
than the local datastore.isClient to true and isServer to false in AtRpcClient,
enabling same atSign communication of AtRpc clients and servers.chore(deps): at_persistence_secondary_server ^4.2.0
feat: deprecate the (misleadingly named) AtClientPreference.Atsign ProtocolEmitted and change its default value from 1.5.0 to 2.0.0
AtClientPreference.Atsign ProtocolEmitted and change its default value
from 1.5.0 to 2.0.0fix: ensure that namespaces in notify requests aren't messed up by multipart namespaces in AtClientPreference (e.g. namespace of foo.bar)
notify requests aren't messed up by
multipart namespaces in AtClientPreference (e.g. namespace of foo.bar)fix: ensure that namespace is preserved if it happens to be repeated in a notification's key (e.g. @bob:foo.my_app.my_app@alice )
@bob:foo.my_app.my_app@alice )feat: add atLookUp parameter to AtClientManager.setCurrentAtSign, AtClientImpl.create, etc. so we can inject an existing AtLookUp instance if we have
atLookUp parameter to AtClientManager.setCurrentAtSign,
AtClientImpl.create, etc. so we can inject an existing AtLookUp instance if
we have one rather than having to create a new one and authenticate againfix[performance]: when fetching public:publickey of another atSign from atServer, cache it in local storage instead of depending on sync to take care
public:publickey of another atSign from
atServer, cache it in local storage instead of depending on sync to take
care of that (since programs can disable sync)build[deps]: update dependencies including at_persistence major version changes
AtKeyNotFoundExceptions in
AtCollectionQueryOperationsImpllocal key, in which case the answer is always yes.build[deps]: update dependencies (at_commons, at_lookup, at_auth)
fix: potential bug handling atSigns which end in data e.g. @foo_data
data e.g. @foo_datafeat: Allows clients to skip delete commits until a specific commitID during initial sync
fix: remove deprecated isPaginated param from SyncVerbBuilder in SyncServiceImpl
feat: add the AtClientBindings mixin which was initially added to the noports_core package but has broader applicability.
build[deps]: Upgraded dependencies for the following packages:
feat: add optional param encryptValue to notify method
encryptValue to notify methodfeat: add allowAll flag (defaults to false) to AtRpc
allowAll flag (defaults to false) to AtRpcfeat: add useRemoteAtServer flag to GetRequestOptions to allow clients to fetch directly from the atServer rather than the client-side synced cache. T
useRemoteAtServer flag to GetRequestOptions to allow clients
to fetch directly from the atServer rather than the client-side synced
cache. This flag was added to PutRequestOptions and
DeleteRequestOptions in version 3.0.60NotificationResponseTransformer does not attempt to
decrypt when atNotification.isEncrypted == falsechore: publish clean version 3.0.78
fix: deprecate NotificationParams.forText and messageType getter by @srieteja in #1314
Full Changelog: v3.0.76...v3.0.77
fix: remove incorrect version 3.0.78 from changelog
fix: melos bootstrapping issues by @xavierchanth in #1217
Full Changelog: v3.0.73...v3.0.76
feat: Introduce feature to fetch enrollment requests from the server
build[deps]: Upgraded dependencies for the following packages:
https://pub.dev/packages/at_client/changelog#3073
https://pub.dev/packages/at_client/changelog#3073
Full Changelog: v3.0.72...v3.0.73
…and after 3.2.0 specifically for this Dart breaking change which was introduced in dart 3.2.0
https://pub.dev/packages/at_client/changelog#3072
Minor change to allow us to support dart versions both before and after 3.2.0 specifically for this Dart breaking change which was introduced in dart 3.2.0
Full Changelog: v3.0.71...v3.0.72
build(deps): bump appleboy/ssh-action from 1.0.1 to 1.0.2 by @dependabot in #1191
build[deps]: Upgraded dependencies for the following packages:
>=1.4.1 <=1.5.0, crypton: >=2.1.0 <=2.2.1, encrypt: >=5.0.1 <=5.0.3, crypto: ^3.0.3feat: Add AtRpcClient for a much cleaner developer experience for sending AtRpc requests
feat: have AtRpc use ephemeral notifications
feat: Make enrollment available to SyncService/NotificationService for authentication
feat: deprecate useAtChops experimental flag and remove fallback code using private key from preferences/EncryptionUtil methods
'3.0.57', at_chops to '1.0.5, at_persistence_secondary_server to '3.0.59'feat: apkam changes for at_onboarding_cli
'3.0.55', at_chops to '1.0.4, at_lookup to '3.0.40'Made ConnectivityListener configurable, and removed some unnecessary network availability checks
socket.listen() in a runZonedGuarded blockfix: Fixed bug in AtRpc.sendRequest which was causing repeat sends of requests
fix: skip reserved keys during sync conflict checking
'>=0.13.5 <2.0.0'fix: ensure key exchange functions properly when the sync service is not being used
feat: add useRemoteAtServer to PutRequestOptions and (new) DeleteRequestOptions by @gkc in #1025
useRemoteAtServer to PutRequestOptions and (new) DeleteRequestOptions by @gkc in #1025useRemoteAtServer to PutRequestOptions. When set, the update
request will be sent directly to the remote atServerdeleteRequestOptions to AtClient.deleteuseRemoteAtServer to DeleteRequestOptions. When set, the delete
request will be sent directly to the remote atServerfix: Sync running into infinite loop when an invalid key is present in the entries to sync into client
chore: upgrade dependencies. at_commons to 3.0.43, at_utils to 3.0.12, at_lookup to 3.0.36 and at_chops to 1.0.3
feat: Initial support of additional encryption metadata enabling encryption future-proofing
AtKeysfix: AtClient.put() throws null-check error when key's namespace is null
fix: Amend Monitor's socket message handler so that it separates multiple 'simultaneous' responses correctly.
fix: ensure forText notifications are decrypted successfully when using at_commons 3.0.35 or greater
build(deps): bump github/codeql-action from 2.1.37 to 2.1.38 by @dependabot in #881
Full Changelog: v3.0.51...v3.0.53
feat: Introduce AtServiceFactory to make AtClientManager more reusable and more testable
Your coding agent can read these notes before it upgrades. Set up the MCP server →